← Vulnerability feed

Vulnerability record · CVE-2019-20489 · published 2 March 2020

CVE-2019-20489: Netgear wnr1000 firmware improper authentication vulnerability

Netgear · Wnr1000 Firmware

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header in the 401 Unauthorized response, and then repeats the FW_remote.htm&todo=cfg_init request with the specified cookie.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 30.9% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 5.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header in the 401 Unauthorized response, and then repeats the FW_remote.htm&todo=cfg_init request with the specified cookie.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-20488Netgear wnr1000 firmware os command injection vulnerabilityAn issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com…EPSS 2.1%9.8CVE-2013-3316Netgear wnr1000 firmware improper authentication vulnerabilityNetgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".EPSS 4.8%9.8CVE-2013-3317Netgear wnr1000 firmware improper authentication vulnerabilityNetgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.EPSS 4.8%8.8CVE-2018-21226Netgear jnr1010 firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1…EPSS 0.70%8.8CVE-2018-21169Netgear d7000 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7000 before 2018-03-01, D7800 before 1.0.1.31, D8…EPSS 0.63%8.8CVE-2017-18703Netgear d1500 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50,…EPSS 0.46%8.8CVE-2017-18737Netgear jnr1010 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…EPSS 1.8%8.8CVE-2017-18734Netgear jnr1010 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2019-20489), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.